Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
main_x86.elf

Overview

General Information

Sample name:main_x86.elf
Analysis ID:1554760
MD5:973753be993886dbe6ee7f1977af48e4
SHA1:b5b8b740af9f6c5f0d95f83861d0421a97bdb328
SHA256:358b4c144624394be7ff769bece8b0783b8a0afdfedb968ac2738a9f46277181
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample deletes itself
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1554760
Start date and time:2024-11-12 21:25:40 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 14s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:main_x86.elf
Detection:MAL
Classification:mal80.troj.evad.linELF@0/0@70/0
  • VT rate limit hit for: main_x86.elf
Command:/tmp/main_x86.elf
PID:5532
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • main_x86.elf (PID: 5532, Parent: 5449, MD5: 973753be993886dbe6ee7f1977af48e4) Arguments: /tmp/main_x86.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
main_x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    main_x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xfb10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfb24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfb38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfb4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfb60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfb74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfb88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfb9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfbb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfbc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfbd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfbec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfc8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xfca0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    main_x86.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xf9f0:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    main_x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0x3dd0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    main_x86.elfLinux_Trojan_Mirai_5f7b67b8unknownunknown
    • 0x8756:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
    Click to see the 4 entries
    SourceRuleDescriptionAuthorStrings
    5532.1.0000000008048000.000000000805a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5532.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xfb10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfb24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfb38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfb4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfb60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfb74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfb88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfb9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfbb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfbc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfbd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfbec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfc8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xfca0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5532.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xf9f0:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      5532.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x3dd0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      5532.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_5f7b67b8unknownunknown
      • 0x8756:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
      Click to see the 7 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: main_x86.elfAvira: detected
      Source: main_x86.elfReversingLabs: Detection: 55%
      Source: main_x86.elfJoe Sandbox ML: detected
      Source: unknownDNS traffic detected: query: Z][@GN)Z[W@J\ replaycode: Name error (3)
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: unknownTCP traffic detected without corresponding DNS query: 115.11.111.11
      Source: global trafficDNS traffic detected: DNS query: Z][@GN)Z[W@J\

      System Summary

      barindex
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: Process Memory Space: main_x86.elf PID: 5532, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: main_x86.elf PID: 5532, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Initial sampleString containing 'busybox' found: /bin/busybox
      Source: Initial sampleString containing 'busybox' found: /proc/opendir/proc/%d/exe/proc/%d/maps/bin/busybox/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/telnetsshwatchdogsshd/usr/compress/bin//compress/bin/compress/usr/bashmain_x86main_x86_64main_mipsmain_mipselmain_armmain_arm5main_arm6main_arm7main_ppcmain_m68kmain_sh4main_spchttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt//tmp/var/mnt/boot/home/dev/..//root(deleted)(condi/exe) Killed process: %s, PID: %d
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: /tmp/main_x86.elf (PID: 5534)SIGKILL sent: pid: 2, result: successfulJump to behavior
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: main_x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: Process Memory Space: main_x86.elf PID: 5532, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: main_x86.elf PID: 5532, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: classification engineClassification label: mal80.troj.evad.linELF@0/0@70/0

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/main_x86.elf (PID: 5532)File: /tmp/main_x86.elfJump to behavior

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: main_x86.elf, type: SAMPLE
      Source: Yara matchFile source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: main_x86.elf PID: 5532, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: main_x86.elf, type: SAMPLE
      Source: Yara matchFile source: 5532.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: main_x86.elf PID: 5532, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
      File Deletion
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Non-Application Layer Protocol
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      main_x86.elf55%ReversingLabsLinux.Backdoor.Mirai
      main_x86.elf100%AviraEXP/ELF.Mirai.Z.A
      main_x86.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      115.11.111.11
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      No context
      No context
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      KIXS-AS-KRKoreaTelecomKRyakuza.arm5.elfGet hashmaliciousUnknownBrowse
      • 175.250.120.21
      yakuza.i586.elfGet hashmaliciousUnknownBrowse
      • 125.154.38.208
      meerkat.ppc.elfGet hashmaliciousMiraiBrowse
      • 112.167.117.175
      meerkat.mips.elfGet hashmaliciousMiraiBrowse
      • 125.157.2.78
      meerkat.x86.elfGet hashmaliciousMiraiBrowse
      • 125.142.230.159
      meerkat.mpsl.elfGet hashmaliciousMiraiBrowse
      • 14.82.112.135
      meerkat.sh4.elfGet hashmaliciousMiraiBrowse
      • 121.147.191.104
      meerkat.arm.elfGet hashmaliciousMiraiBrowse
      • 220.124.201.88
      ORDER NHL121124.xlsGet hashmaliciousHTMLPhisherBrowse
      • 221.146.204.133
      2024-HRDCL-0000796.xlsGet hashmaliciousRemcos, HTMLPhisherBrowse
      • 221.146.204.133
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
      Entropy (8bit):5.733376978246394
      TrID:
      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
      File name:main_x86.elf
      File size:89'992 bytes
      MD5:973753be993886dbe6ee7f1977af48e4
      SHA1:b5b8b740af9f6c5f0d95f83861d0421a97bdb328
      SHA256:358b4c144624394be7ff769bece8b0783b8a0afdfedb968ac2738a9f46277181
      SHA512:f5d2de95f0f162c67c56fbfc80e8857e2ad51c14ad0e6bda40150c015fd6ec8913524c834c63bb9d26eb252b86dd5736df66c100ce895b392ee0dd12d9cf8607
      SSDEEP:1536:W/QCZaxGdvts3i5JPhoOAxPu++AjloUIKqI4FrS4LS/:WYCZa8dvm3oJPhDAxP5JlKKfUmD/
      TLSH:15937CC0F683C4F2E84705B1507BE7379B32F1B9101AFA43D3699A72DC91551EA1AB9C
      File Content Preview:.ELF....................d...4....]......4. ...(......................................................G..`...........Q.td............................U..S........%...h........[]...$.............U......=.....t..5....D......D.......u........t....h............

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:Intel 80386
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - System V
      ABI Version:0
      Entry Point Address:0x8048164
      Flags:0x0
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:89592
      Section Header Size:40
      Number of Section Headers:10
      Header String Table Index:9
      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
      NULL0x00x00x00x00x0000
      .initPROGBITS0x80480940x940x1c0x00x6AX001
      .textPROGBITS0x80480b00xb00xf2060x00x6AX0016
      .finiPROGBITS0x80572b60xf2b60x170x00x6AX001
      .rodataPROGBITS0x80572e00xf2e00x23280x00x2A0032
      .ctorsPROGBITS0x805a60c0x1160c0xc0x00x3WA004
      .dtorsPROGBITS0x805a6180x116180x80x00x3WA004
      .dataPROGBITS0x805a6400x116400x47780x00x3WA0032
      .bssNOBITS0x805edc00x15db80x59ac0x00x3WA0032
      .shstrtabSTRTAB0x00x15db80x3e0x00x0001
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x80480000x80480000x116080x116086.60530x5R E0x1000.init .text .fini .rodata
      LOAD0x1160c0x805a60c0x805a60c0x47ac0xa1600.37500x6RW 0x1000.ctors .dtors .data .bss
      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
      TimestampSource PortDest PortSource IPDest IP
      Nov 12, 2024 21:26:24.757888079 CET5589022192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:24.762810946 CET2255890115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:24.762881041 CET5589022192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:24.762929916 CET5589022192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:24.767853975 CET2255890115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:24.767899990 CET5589022192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:24.772723913 CET2255890115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:33.269968033 CET2255890115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:33.270148993 CET5589022192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:33.275073051 CET2255890115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:34.309205055 CET5589222192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:34.314223051 CET2255892115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:34.314274073 CET5589222192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:34.314289093 CET5589222192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:34.319822073 CET2255892115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:34.319870949 CET5589222192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:34.325587988 CET2255892115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:42.814367056 CET2255892115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:42.814461946 CET5589222192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:42.820521116 CET2255892115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:43.853238106 CET5589422192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:43.858149052 CET2255894115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:43.858202934 CET5589422192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:43.858217955 CET5589422192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:43.863337994 CET2255894115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:43.863384962 CET5589422192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:43.868339062 CET2255894115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:52.364917994 CET2255894115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:52.365012884 CET5589422192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:52.371860981 CET2255894115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:53.402812004 CET5589622192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:53.407716990 CET2255896115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:53.407852888 CET5589622192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:53.407877922 CET5589622192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:53.412916899 CET2255896115.11.111.11192.168.2.15
      Nov 12, 2024 21:26:53.413002968 CET5589622192.168.2.15115.11.111.11
      Nov 12, 2024 21:26:53.417859077 CET2255896115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:01.890049934 CET2255896115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:01.890263081 CET5589622192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:01.896012068 CET2255896115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:02.929367065 CET5589822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:02.934262991 CET2255898115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:02.934348106 CET5589822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:02.934457064 CET5589822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:02.939208984 CET2255898115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:02.939260960 CET5589822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:02.944298983 CET2255898115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:11.420048952 CET2255898115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:11.420361996 CET5589822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:11.426330090 CET2255898115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:12.460957050 CET5590022192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:12.466033936 CET2255900115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:12.466105938 CET5590022192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:12.466186047 CET5590022192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:12.470926046 CET2255900115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:12.470993996 CET5590022192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:12.476376057 CET2255900115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:20.952085972 CET2255900115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:20.952238083 CET5590022192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:20.957336903 CET2255900115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:21.990978956 CET5590222192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:21.995991945 CET2255902115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:21.996078968 CET5590222192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:21.996107101 CET5590222192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:22.000947952 CET2255902115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:22.000996113 CET5590222192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:22.006079912 CET2255902115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:30.497761011 CET2255902115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:30.497958899 CET5590222192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:30.503489017 CET2255902115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:31.536781073 CET5590422192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:31.541791916 CET2255904115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:31.541872025 CET5590422192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:31.541908979 CET5590422192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:31.547043085 CET2255904115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:31.547127962 CET5590422192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:31.552141905 CET2255904115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:40.046499014 CET2255904115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:40.046662092 CET5590422192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:40.053272963 CET2255904115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:41.085542917 CET5590622192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:41.090444088 CET2255906115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:41.090545893 CET5590622192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:41.090559006 CET5590622192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:41.096327066 CET2255906115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:41.096426964 CET5590622192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:41.101497889 CET2255906115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:49.568929911 CET2255906115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:49.569142103 CET5590622192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:49.574120998 CET2255906115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:50.607836008 CET5590822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:50.612752914 CET2255908115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:50.612838984 CET5590822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:50.612859011 CET5590822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:50.617839098 CET2255908115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:50.617902040 CET5590822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:50.623209953 CET2255908115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:59.089298964 CET2255908115.11.111.11192.168.2.15
      Nov 12, 2024 21:27:59.089471102 CET5590822192.168.2.15115.11.111.11
      Nov 12, 2024 21:27:59.094398975 CET2255908115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:00.127381086 CET5591022192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:00.132273912 CET2255910115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:00.132385015 CET5591022192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:00.132430077 CET5591022192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:00.137296915 CET2255910115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:00.137375116 CET5591022192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:00.142209053 CET2255910115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:08.613990068 CET2255910115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:08.614288092 CET5591022192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:08.619138956 CET2255910115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:09.654309988 CET5591222192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:09.659497976 CET2255912115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:09.659607887 CET5591222192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:09.659634113 CET5591222192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:09.664876938 CET2255912115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:09.664958000 CET5591222192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:09.669816017 CET2255912115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:18.165196896 CET2255912115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:18.165641069 CET5591222192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:18.170644999 CET2255912115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:19.204380989 CET5591422192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:19.209424973 CET2255914115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:19.209500074 CET5591422192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:19.209522009 CET5591422192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:19.214570045 CET2255914115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:19.214624882 CET5591422192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:19.219526052 CET2255914115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:27.695389032 CET2255914115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:27.695611954 CET5591422192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:27.700598001 CET2255914115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:28.751765013 CET5591622192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:28.759995937 CET2255916115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:28.760085106 CET5591622192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:28.760123014 CET5591622192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:28.768610954 CET2255916115.11.111.11192.168.2.15
      Nov 12, 2024 21:28:28.768675089 CET5591622192.168.2.15115.11.111.11
      Nov 12, 2024 21:28:28.774602890 CET2255916115.11.111.11192.168.2.15
      TimestampSource PortDest PortSource IPDest IP
      Nov 12, 2024 21:26:24.721174002 CET5997253192.168.2.158.8.8.8
      Nov 12, 2024 21:26:24.728607893 CET53599728.8.8.8192.168.2.15
      Nov 12, 2024 21:26:24.728698015 CET4427653192.168.2.158.8.8.8
      Nov 12, 2024 21:26:24.735891104 CET53442768.8.8.8192.168.2.15
      Nov 12, 2024 21:26:24.736016989 CET5931853192.168.2.158.8.8.8
      Nov 12, 2024 21:26:24.743029118 CET53593188.8.8.8192.168.2.15
      Nov 12, 2024 21:26:24.743132114 CET4212053192.168.2.158.8.8.8
      Nov 12, 2024 21:26:24.750224113 CET53421208.8.8.8192.168.2.15
      Nov 12, 2024 21:26:24.750320911 CET5363853192.168.2.158.8.8.8
      Nov 12, 2024 21:26:24.757785082 CET53536388.8.8.8192.168.2.15
      Nov 12, 2024 21:26:34.271267891 CET3278653192.168.2.158.8.8.8
      Nov 12, 2024 21:26:34.278789043 CET53327868.8.8.8192.168.2.15
      Nov 12, 2024 21:26:34.278866053 CET5210253192.168.2.158.8.8.8
      Nov 12, 2024 21:26:34.286233902 CET53521028.8.8.8192.168.2.15
      Nov 12, 2024 21:26:34.286282063 CET4487853192.168.2.158.8.8.8
      Nov 12, 2024 21:26:34.294118881 CET53448788.8.8.8192.168.2.15
      Nov 12, 2024 21:26:34.294179916 CET5187853192.168.2.158.8.8.8
      Nov 12, 2024 21:26:34.301266909 CET53518788.8.8.8192.168.2.15
      Nov 12, 2024 21:26:34.301326990 CET5861453192.168.2.158.8.8.8
      Nov 12, 2024 21:26:34.309138060 CET53586148.8.8.8192.168.2.15
      Nov 12, 2024 21:26:43.815377951 CET3469353192.168.2.158.8.8.8
      Nov 12, 2024 21:26:43.822771072 CET53346938.8.8.8192.168.2.15
      Nov 12, 2024 21:26:43.822856903 CET4887753192.168.2.158.8.8.8
      Nov 12, 2024 21:26:43.830858946 CET53488778.8.8.8192.168.2.15
      Nov 12, 2024 21:26:43.830910921 CET4491253192.168.2.158.8.8.8
      Nov 12, 2024 21:26:43.838239908 CET53449128.8.8.8192.168.2.15
      Nov 12, 2024 21:26:43.838295937 CET4816653192.168.2.158.8.8.8
      Nov 12, 2024 21:26:43.845520020 CET53481668.8.8.8192.168.2.15
      Nov 12, 2024 21:26:43.845575094 CET3868053192.168.2.158.8.8.8
      Nov 12, 2024 21:26:43.853167057 CET53386808.8.8.8192.168.2.15
      Nov 12, 2024 21:26:53.365973949 CET4486853192.168.2.158.8.8.8
      Nov 12, 2024 21:26:53.373744965 CET53448688.8.8.8192.168.2.15
      Nov 12, 2024 21:26:53.373820066 CET4002053192.168.2.158.8.8.8
      Nov 12, 2024 21:26:53.381305933 CET53400208.8.8.8192.168.2.15
      Nov 12, 2024 21:26:53.381360054 CET6095753192.168.2.158.8.8.8
      Nov 12, 2024 21:26:53.388628960 CET53609578.8.8.8192.168.2.15
      Nov 12, 2024 21:26:53.388679981 CET5634253192.168.2.158.8.8.8
      Nov 12, 2024 21:26:53.395551920 CET53563428.8.8.8192.168.2.15
      Nov 12, 2024 21:26:53.395615101 CET5967853192.168.2.158.8.8.8
      Nov 12, 2024 21:26:53.402743101 CET53596788.8.8.8192.168.2.15
      Nov 12, 2024 21:27:02.891545057 CET3689653192.168.2.158.8.8.8
      Nov 12, 2024 21:27:02.898881912 CET53368968.8.8.8192.168.2.15
      Nov 12, 2024 21:27:02.899004936 CET4828553192.168.2.158.8.8.8
      Nov 12, 2024 21:27:02.907085896 CET53482858.8.8.8192.168.2.15
      Nov 12, 2024 21:27:02.907176018 CET3462353192.168.2.158.8.8.8
      Nov 12, 2024 21:27:02.914470911 CET53346238.8.8.8192.168.2.15
      Nov 12, 2024 21:27:02.914550066 CET4443153192.168.2.158.8.8.8
      Nov 12, 2024 21:27:02.921925068 CET53444318.8.8.8192.168.2.15
      Nov 12, 2024 21:27:02.922008038 CET3912153192.168.2.158.8.8.8
      Nov 12, 2024 21:27:02.929259062 CET53391218.8.8.8192.168.2.15
      Nov 12, 2024 21:27:12.421730995 CET4551753192.168.2.158.8.8.8
      Nov 12, 2024 21:27:12.429480076 CET53455178.8.8.8192.168.2.15
      Nov 12, 2024 21:27:12.429640055 CET4053153192.168.2.158.8.8.8
      Nov 12, 2024 21:27:12.436577082 CET53405318.8.8.8192.168.2.15
      Nov 12, 2024 21:27:12.436682940 CET3345053192.168.2.158.8.8.8
      Nov 12, 2024 21:27:12.445557117 CET53334508.8.8.8192.168.2.15
      Nov 12, 2024 21:27:12.445677996 CET3394953192.168.2.158.8.8.8
      Nov 12, 2024 21:27:12.453030109 CET53339498.8.8.8192.168.2.15
      Nov 12, 2024 21:27:12.453125954 CET5570253192.168.2.158.8.8.8
      Nov 12, 2024 21:27:12.460850954 CET53557028.8.8.8192.168.2.15
      Nov 12, 2024 21:27:21.953572035 CET4247553192.168.2.158.8.8.8
      Nov 12, 2024 21:27:21.960903883 CET53424758.8.8.8192.168.2.15
      Nov 12, 2024 21:27:21.961067915 CET3506053192.168.2.158.8.8.8
      Nov 12, 2024 21:27:21.968240023 CET53350608.8.8.8192.168.2.15
      Nov 12, 2024 21:27:21.968409061 CET3743553192.168.2.158.8.8.8
      Nov 12, 2024 21:27:21.975708008 CET53374358.8.8.8192.168.2.15
      Nov 12, 2024 21:27:21.975824118 CET4175553192.168.2.158.8.8.8
      Nov 12, 2024 21:27:21.983303070 CET53417558.8.8.8192.168.2.15
      Nov 12, 2024 21:27:21.983413935 CET4876753192.168.2.158.8.8.8
      Nov 12, 2024 21:27:21.990837097 CET53487678.8.8.8192.168.2.15
      Nov 12, 2024 21:27:31.499283075 CET3896253192.168.2.158.8.8.8
      Nov 12, 2024 21:27:31.507049084 CET53389628.8.8.8192.168.2.15
      Nov 12, 2024 21:27:31.507179022 CET4301953192.168.2.158.8.8.8
      Nov 12, 2024 21:27:31.514651060 CET53430198.8.8.8192.168.2.15
      Nov 12, 2024 21:27:31.514776945 CET4360753192.168.2.158.8.8.8
      Nov 12, 2024 21:27:31.522092104 CET53436078.8.8.8192.168.2.15
      Nov 12, 2024 21:27:31.522237062 CET6038953192.168.2.158.8.8.8
      Nov 12, 2024 21:27:31.529656887 CET53603898.8.8.8192.168.2.15
      Nov 12, 2024 21:27:31.529762983 CET4125453192.168.2.158.8.8.8
      Nov 12, 2024 21:27:31.536663055 CET53412548.8.8.8192.168.2.15
      Nov 12, 2024 21:27:41.048015118 CET5690353192.168.2.158.8.8.8
      Nov 12, 2024 21:27:41.055850029 CET53569038.8.8.8192.168.2.15
      Nov 12, 2024 21:27:41.055980921 CET4324853192.168.2.158.8.8.8
      Nov 12, 2024 21:27:41.063296080 CET53432488.8.8.8192.168.2.15
      Nov 12, 2024 21:27:41.063400984 CET5213453192.168.2.158.8.8.8
      Nov 12, 2024 21:27:41.070667028 CET53521348.8.8.8192.168.2.15
      Nov 12, 2024 21:27:41.070785999 CET4405653192.168.2.158.8.8.8
      Nov 12, 2024 21:27:41.078150034 CET53440568.8.8.8192.168.2.15
      Nov 12, 2024 21:27:41.078249931 CET3999953192.168.2.158.8.8.8
      Nov 12, 2024 21:27:41.085444927 CET53399998.8.8.8192.168.2.15
      Nov 12, 2024 21:27:50.570451021 CET5612853192.168.2.158.8.8.8
      Nov 12, 2024 21:27:50.577589035 CET53561288.8.8.8192.168.2.15
      Nov 12, 2024 21:27:50.577730894 CET4462853192.168.2.158.8.8.8
      Nov 12, 2024 21:27:50.584877014 CET53446288.8.8.8192.168.2.15
      Nov 12, 2024 21:27:50.584981918 CET5648753192.168.2.158.8.8.8
      Nov 12, 2024 21:27:50.592968941 CET53564878.8.8.8192.168.2.15
      Nov 12, 2024 21:27:50.593075037 CET4277253192.168.2.158.8.8.8
      Nov 12, 2024 21:27:50.600045919 CET53427728.8.8.8192.168.2.15
      Nov 12, 2024 21:27:50.600173950 CET3625053192.168.2.158.8.8.8
      Nov 12, 2024 21:27:50.607729912 CET53362508.8.8.8192.168.2.15
      Nov 12, 2024 21:28:00.090837002 CET4101553192.168.2.158.8.8.8
      Nov 12, 2024 21:28:00.098593950 CET53410158.8.8.8192.168.2.15
      Nov 12, 2024 21:28:00.098697901 CET5579753192.168.2.158.8.8.8
      Nov 12, 2024 21:28:00.105601072 CET53557978.8.8.8192.168.2.15
      Nov 12, 2024 21:28:00.105727911 CET3498053192.168.2.158.8.8.8
      Nov 12, 2024 21:28:00.112988949 CET53349808.8.8.8192.168.2.15
      Nov 12, 2024 21:28:00.113084078 CET4391953192.168.2.158.8.8.8
      Nov 12, 2024 21:28:00.120346069 CET53439198.8.8.8192.168.2.15
      Nov 12, 2024 21:28:00.120451927 CET3549253192.168.2.158.8.8.8
      Nov 12, 2024 21:28:00.127260923 CET53354928.8.8.8192.168.2.15
      Nov 12, 2024 21:28:09.616400003 CET3494053192.168.2.158.8.8.8
      Nov 12, 2024 21:28:09.624130964 CET53349408.8.8.8192.168.2.15
      Nov 12, 2024 21:28:09.624314070 CET4594553192.168.2.158.8.8.8
      Nov 12, 2024 21:28:09.631449938 CET53459458.8.8.8192.168.2.15
      Nov 12, 2024 21:28:09.631620884 CET3862853192.168.2.158.8.8.8
      Nov 12, 2024 21:28:09.638803005 CET53386288.8.8.8192.168.2.15
      Nov 12, 2024 21:28:09.638976097 CET5066053192.168.2.158.8.8.8
      Nov 12, 2024 21:28:09.646148920 CET53506608.8.8.8192.168.2.15
      Nov 12, 2024 21:28:09.646286964 CET5223353192.168.2.158.8.8.8
      Nov 12, 2024 21:28:09.654165983 CET53522338.8.8.8192.168.2.15
      Nov 12, 2024 21:28:19.167057991 CET3668553192.168.2.158.8.8.8
      Nov 12, 2024 21:28:19.175050020 CET53366858.8.8.8192.168.2.15
      Nov 12, 2024 21:28:19.175180912 CET4976753192.168.2.158.8.8.8
      Nov 12, 2024 21:28:19.182857037 CET53497678.8.8.8192.168.2.15
      Nov 12, 2024 21:28:19.182938099 CET5440553192.168.2.158.8.8.8
      Nov 12, 2024 21:28:19.189928055 CET53544058.8.8.8192.168.2.15
      Nov 12, 2024 21:28:19.190017939 CET5650053192.168.2.158.8.8.8
      Nov 12, 2024 21:28:19.196906090 CET53565008.8.8.8192.168.2.15
      Nov 12, 2024 21:28:19.196959019 CET5663653192.168.2.158.8.8.8
      Nov 12, 2024 21:28:19.204274893 CET53566368.8.8.8192.168.2.15
      Nov 12, 2024 21:28:28.697738886 CET5774553192.168.2.158.8.8.8
      Nov 12, 2024 21:28:28.710980892 CET53577458.8.8.8192.168.2.15
      Nov 12, 2024 21:28:28.711170912 CET4081453192.168.2.158.8.8.8
      Nov 12, 2024 21:28:28.721286058 CET53408148.8.8.8192.168.2.15
      Nov 12, 2024 21:28:28.721400976 CET4133953192.168.2.158.8.8.8
      Nov 12, 2024 21:28:28.730601072 CET53413398.8.8.8192.168.2.15
      Nov 12, 2024 21:28:28.730705976 CET4185753192.168.2.158.8.8.8
      Nov 12, 2024 21:28:28.741132021 CET53418578.8.8.8192.168.2.15
      Nov 12, 2024 21:28:28.741220951 CET5908853192.168.2.158.8.8.8
      Nov 12, 2024 21:28:28.751658916 CET53590888.8.8.8192.168.2.15
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Nov 12, 2024 21:26:24.721174002 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.728698015 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.736016989 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.743132114 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.750320911 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.271267891 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.278866053 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.286282063 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.294179916 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.301326990 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.815377951 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.822856903 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.830910921 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.838295937 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.845575094 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.365973949 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.373820066 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.381360054 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.388679981 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.395615101 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.891545057 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.899004936 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.907176018 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.914550066 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.922008038 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.421730995 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.429640055 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.436682940 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.445677996 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.453125954 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.953572035 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.961067915 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.968409061 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.975824118 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.983413935 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.499283075 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.507179022 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.514776945 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.522237062 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.529762983 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.048015118 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.055980921 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.063400984 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.070785999 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.078249931 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.570451021 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.577730894 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.584981918 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.593075037 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.600173950 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.090837002 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.098697901 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.105727911 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.113084078 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.120451927 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.616400003 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.624314070 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.631620884 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.638976097 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.646286964 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.167057991 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.175180912 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.182938099 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.190017939 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.196959019 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.697738886 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.711170912 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.721400976 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.730705976 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.741220951 CET192.168.2.158.8.8.80x0Standard query (0)Z][@GN)Z[W@J\A (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Nov 12, 2024 21:26:24.728607893 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.735891104 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.743029118 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.750224113 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:24.757785082 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.278789043 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.286233902 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.294118881 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.301266909 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:34.309138060 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.822771072 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.830858946 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.838239908 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.845520020 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:43.853167057 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.373744965 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.381305933 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.388628960 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.395551920 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:26:53.402743101 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.898881912 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.907085896 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.914470911 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.921925068 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:02.929259062 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.429480076 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.436577082 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.445557117 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.453030109 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:12.460850954 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.960903883 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.968240023 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.975708008 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.983303070 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:21.990837097 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.507049084 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.514651060 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.522092104 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.529656887 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:31.536663055 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.055850029 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.063296080 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.070667028 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.078150034 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:41.085444927 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.577589035 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.584877014 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.592968941 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.600045919 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:27:50.607729912 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.098593950 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.105601072 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.112988949 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.120346069 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:00.127260923 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.624130964 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.631449938 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.638803005 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.646148920 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:09.654165983 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.175050020 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.182857037 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.189928055 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.196906090 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:19.204274893 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.710980892 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.721286058 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.730601072 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.741132021 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false
      Nov 12, 2024 21:28:28.751658916 CET8.8.8.8192.168.2.150x0Name error (3)Z][@GN)Z[W@J\nonenoneA (IP address)IN (0x0001)false

      System Behavior

      Start time (UTC):20:26:24
      Start date (UTC):12/11/2024
      Path:/tmp/main_x86.elf
      Arguments:/tmp/main_x86.elf
      File size:89992 bytes
      MD5 hash:973753be993886dbe6ee7f1977af48e4

      Start time (UTC):20:26:24
      Start date (UTC):12/11/2024
      Path:/tmp/main_x86.elf
      Arguments:-
      File size:89992 bytes
      MD5 hash:973753be993886dbe6ee7f1977af48e4

      Start time (UTC):20:26:24
      Start date (UTC):12/11/2024
      Path:/tmp/main_x86.elf
      Arguments:-
      File size:89992 bytes
      MD5 hash:973753be993886dbe6ee7f1977af48e4